CVE-2005-3010
CuteNews <1.4.0 - Code Injection
Title source: llmDescription
Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php.
Exploits (1)
Scores
EPSS
0.0243
EPSS Percentile
85.2%
Details
Status
published
Products (1)
cutephp/cutenews
< 1.4.0
Published
Sep 21, 2005
Tracked Since
Feb 18, 2026